Standard contractual clauses

Moving personal data out of Europe,
on terms that hold up.

Standard contractual clauses are how most companies send personal data from the EU and UK to the rest of the world. This guide covers the four 2021 SCC modules, what a transfer impact assessment involves, where the EU-US Data Privacy Framework stands in October 2026, and the UK's IDTA and Addendum. Not legal advice.

GDPR Art. 46Decision (EU) 2021/914EDPB Rec. 01/2020EU-US DPFUK IDTAUK Addendum

Last updated Published by TryTrustableNot legal advice

Short answer

Standard contractual clauses (SCCs) are model contract terms adopted by the European Commission that let a company transfer personal data out of the EEA to a country without an adequacy decision. The current set, adopted on 4 June 2021 in Decision (EU) 2021/914, has four modules for controller and processor combinations. Signing them is not enough on its own: Clause 14 requires both parties to assess whether the destination country's laws and practices let the importer comply, and to document that transfer impact assessment. The UK uses its own IDTA, or an Addendum to the EU SCCs.

01

What are standard contractual clauses?

The GDPR restricts transfers of personal data to countries outside the EEA (Article 44). A transfer is allowed if the destination has an adequacy decision (Article 45), if appropriate safeguards are in place (Article 46), or, for occasional transfers, under a narrow derogation such as explicit consent (Article 49). Standard contractual clauses are the most used safeguard: Article 46(2)(c) lets parties rely on clauses adopted by the Commission without asking a supervisory authority for approval.

The current EU SCCs were adopted on 4 June 2021 in Commission Implementing Decision (EU) 2021/914. The two older sets were repealed from 27 September 2021, and contracts signed on them stopped providing safeguards after 27 December 2022. If a vendor still sends you 2010 clauses, they are out of date. A separate Decision, (EU) 2021/915, provides optional clauses for controller-processor contracts inside the EEA; those are not transfer tools.

02

The four SCC modules

The 2021 SCCs are modular. You pick the module that matches each party's role, and you can combine modules in one document when a relationship involves more than one flow.

ModuleExporter to importerTypical use
OneController to controllerSharing customer data with a partner who uses it for its own purposes
TwoController to processorAn EU company using a non-EU SaaS vendor, support desk or hosting provider
ThreeProcessor to processorAn EU-based SaaS vendor using a non-EU sub-processor for its customers' data
FourProcessor to controllerAn EU processor returning data to a non-EU customer that is its controller

One contract can combine modules. Modules Two and Three also cover the Article 28 processor terms.

03

The clauses that need decisions

The text of the clauses cannot be changed, but several clauses offer options and the annexes must be completed. Annex I describes the parties and the transfer, Annex II the security measures, and Annex III the authorised sub-processors where you choose specific authorisation.

ClauseWhat it doesWhat to decide
7Optional docking clause: new parties can accede laterWhether to include it (it saves re-papering groups)
8Data protection safeguards per module: purpose, transparency, accuracy, security, onward transfersAnnex II security measures, which must be specific, not boilerplate
9Sub-processors (Modules Two and Three)Specific prior authorisation or general authorisation from an agreed list, and the notice period
13Which supervisory authority oversees the transferNamed in Annex I.C
14Local laws and practices: the transfer impact assessmentDocumented assessment, available to the authority on request
15Duties if a public authority asks the importer for the dataNotification, challenge and minimal disclosure
17, 18Governing law and courtsAn EU Member State that allows third-party beneficiary rights (Module Four can choose another country)

Clause numbers from the Annex to Decision (EU) 2021/914.

One gap to know about: Article 1 of the Decision covers importers whose processing is not subject to the GDPR. Where the importer is already directly subject to the GDPR under Article 3(2), the Commission has said it is developing an additional set of SCCs for that case. As of October 2026 its SCC page still describes that work as in progress, so take advice on how to paper those transfers.

04

What is a transfer impact assessment?

A transfer impact assessment (TIA) is the analysis Clause 14 requires before you transfer. Both parties warrant that they have no reason to believe the destination's laws and practices, including rules on government access to data, prevent the importer from meeting the clauses. To give that warranty, Clause 14(b) requires you to take account of:

  • the specific circumstances of the transfer: the processing chain, the parties, the purpose, the categories and format of the data, the sector and where the data is stored;
  • the laws and practices of the destination relevant to those circumstances, and their limits and safeguards;
  • any contractual, technical or organisational safeguards you add, such as encryption where the importer does not hold the keys.

Clause 14(d) requires the assessment to be documented and made available to the supervisory authority on request. The EDPB's Recommendations 01/2020 (final version adopted 18 June 2021) set out the method in six steps: know your transfers; identify the transfer tool; assess whether it is effective given the destination's law and practice; adopt supplementary measures where it is not; take any procedural steps; and re-evaluate at appropriate intervals. If the assessment shows the data cannot be adequately protected, Clause 14(f) requires you to suspend the transfer.

In practice a TIA is a short structured document per vendor or per transfer type. The vendors that matter most are your critical tier: the ones that hold production data. See our vendor risk management guide for how to tier them.

05

The EU-US Data Privacy Framework in October 2026

The Commission adopted its adequacy decision for the EU-US Data Privacy Framework (DPF) on 10 July 2023. A transfer to a US company that has self-certified to the DPF and covers the data you send needs no SCCs or TIA. Transfers to US companies outside the DPF still need SCCs and a TIA. You can check a company's status on the public DPF list, and certifications must be renewed every year.

The framework is in force but contested. On 3 September 2025 the EU General Court dismissed the first challenge to it (Latombe v Commission, T-553/23). In June 2026 the US Supreme Court, in Trump v. Slaughter, held that statutory protections against the President removing Federal Trade Commission members were unconstitutional; the FTC is one of the DPF's enforcement bodies. The privacy group noyb then asked the Commission to repeal the decision and said it would bring an annulment action. Until a court annuls it or the Commission withdraws it, the adequacy decision stands. The two previous EU-US arrangements were both struck down by the Court of Justice, so many companies keep SCCs in their US contracts as a fallback that takes effect if the DPF falls.

06

UK transfers: the IDTA and the Addendum

The UK left the EU SCC system with Brexit. Under the UK GDPR, a restricted transfer needs UK adequacy regulations, an appropriate safeguard, or an exception. The ICO issued two sets of standard clauses, both laid before Parliament on 2 February 2022: the International Data Transfer Agreement (IDTA), and the International Data Transfer Addendum, which makes the EU SCCs work for UK transfers.

ToolWhat it isWhen to use it
IDTAThe ICO's International Data Transfer Agreement: four parts, with tables you complete and mandatory clausesUK-only transfers, or where you want a standalone UK contract
AddendumThe ICO's International Data Transfer Addendum to the EU SCCsYou already use the EU SCCs and want one contract for EU and UK transfers
UK Extension (data bridge)UK adequacy regulations for US businesses certified to the UK Extension of the DPFThe US importer is on the DPF list with an active UK Extension certification
Transfer risk assessmentThe UK's version of a TIA, now called the data protection test: the protection must not be materially lower after transferBefore relying on the IDTA, the Addendum or another safeguard

The EU SCCs alone are not valid for UK restricted transfers. Use the Addendum with them, or the IDTA.

The Data (Use and Access) Act 2025 reworded the UK test: a safeguard can be relied on only if the protection is not materially lower after the transfer, judged reasonably and proportionately. The ICO says this does not materially change how transfers work, plans to update the IDTA and Addendum during 2026, and tells organisations to keep using the current versions; both can be set to update automatically when it does. For transfers in the other direction, the European Commission renewed the UK's EU adequacy decisions on 19 December 2025, and they last until 27 December 2031. The UK Extension for US transfers is the UK's own regulation and, as the ICO clarified in July 2026, is independent of the EU's finding on the US.

07

How TryTrustable tracks transfers

Most transfer failures are paperwork failures: a vendor added without a DPA, a sub-processor in a new country, a contract that expired. The platform keeps the register that catches them.

In TryTrustableWhat it does
Vendor registerEach vendor's tier, the data it touches, and whether a signed DPA is on file
Processor registerContract reference and validity for each processor, and its country checked against destinations you have restricted
ControlsTransfer controls mapped across GDPR, UK GDPR and your other frameworks, with the evidence kept in one ledger

We record and check your transfer paperwork. We do not draft SCCs or carry out TIAs.

Questions

The things people ask us

Are standard contractual clauses still valid in 2026?

Yes. The 2021 SCCs adopted in Decision (EU) 2021/914 remain valid and are the most used transfer tool. The older 2001 and 2010 clauses stopped providing safeguards after 27 December 2022.

Which SCC module do I need?

Match the roles: Module One for controller to controller, Two for controller to processor, Three for processor to sub-processor, Four for processor back to controller. Most SaaS vendor contracts use Module Two.

Do I need a transfer impact assessment if I sign SCCs?

Yes. Clause 14 requires both parties to assess the destination's laws and practices, document it and make it available to the supervisory authority on request.

Do I need SCCs for a US vendor certified to the Data Privacy Framework?

Not while the adequacy decision stands, if the vendor's certification is active and covers the data. Many companies still include SCCs as a fallback in case the framework is annulled.

Can I use the EU SCCs for UK transfers?

Not on their own. Add the ICO's International Data Transfer Addendum, or use the IDTA instead, and complete a transfer risk assessment.

What is the difference between a TIA and a DPIA?

A transfer impact assessment looks at whether a destination country's law lets the importer protect the data. A DPIA looks at the risk of a processing activity to people's rights. A risky transfer can need both.

Does TryTrustable draft SCCs or run TIAs?

No. The platform records which vendors and processors you use, where they are, and whether the contracts are on file and valid. Drafting and assessing stay with you and your counsel.

Book a walkthrough

Know where your vendors are, and what the paperwork says.

Thirty minutes on your vendor list, your transfer contracts and the GDPR and UK GDPR controls behind them.